Coreum-XRPL Bridge Drained in 97-Minute Exploit
A flaw in Coreum’s bridge relayer logic let an attacker drain 199,916 XRP through 94 withdrawals before the bridge was suspended.
A cross-chain bridge connecting Coreum to the XRP Ledger was drained of 199,916 XRP, or roughly $200,000, after an attacker exploited a flaw in the bridge’s deposit-verification logic. The flaw allowed fabricated deposit actions to be treated as genuine and triggered withdrawals for XRP that had not been deposited. The theft unfolded in about 97 minutes on August 9, leaving the bridge with 493.5 XRP.
How the Bridge Approved Withdrawals for Money It Never Received
The exploit did not involve stolen private keys or a breach of the XRP Ledger itself. Instead, the attacker used a flaw in the bridge’s relayer logic, which was meant to verify that deposits on one chain were genuine before authorizing corresponding withdrawals. The system accepted fabricated deposit actions as legitimate, crediting the attacker with XRP that had not been sent to the bridge.
With that balance recorded, the attacker withdrew real XRP through the bridge’s normal process. The drain was carried out through 94 separate withdrawal payments sent to two newly created wallets. Each transaction received approval from 17 of the bridge’s 28 relayer keys, the threshold required for the payments to proceed.
The incident shows how a flaw in deposit verification can affect every transaction that depends on the same relayer process. On-chain analysis identified 94 multisig-authorized payments during the 97-minute window, allowing the attacker to empty nearly all of the bridge’s XRP balance.
Cross-Chain Bridge Risk Is Separate From XRPL Risk
This was not an XRPL protocol failure. The XRP Ledger processed the transactions, while the vulnerability was in third-party bridge software responsible for verifying deposits and authorizing withdrawals between networks. That distinction is relevant for XRP holders who use bridge infrastructure to move assets beyond the ledger.
Cross-chain bridges hold or verify assets on one chain and issue or release an equivalent amount on another. Their security depends on the verification process used to confirm that an action on one network actually occurred before a corresponding action is authorized elsewhere. In Coreum’s case, the relayer-based verification logic accepted fabricated deposit actions, enabling real XRP payouts from the bridge wallet.
For users of cross-chain infrastructure, the incident highlights the importance of understanding how a bridge’s relayers operate, what verification they perform, and whether the bridge can be suspended when suspicious activity is detected.
What Comes Next
As of August 11, the Coreum bridge remained suspended. The Coreum Development Foundation had not released an official incident report, leaving available accounts of the exploit based on on-chain data and independent analysis.
XRP was trading near $1.02 at the time of reporting. The incident was described as a third-party infrastructure failure rather than a vulnerability in XRPL’s core security. For XRP holders using cross-chain services, bridge risk remains separate from the risks of holding or transferring assets directly on the ledger.
Follow CoinNews on X and Telegram for ongoing coverage of bridge security incidents and XRP market developments.